# Secret guard allow-list: KNOWN FAKE values that look like secrets (test # fixtures, docs). Allowed BY HASH (sha256[:8] of the value), so a real secret # in the same file still flags. Private-key blocks (the match is only the BEGIN # line, same hash everywhere) are allowed by PATH + kind instead. # Every entry MUST say why. Owner: Windy Git lane (13); changes via the orchestrator. # Triage 09-24 (values never printed): each hash checked against every version of # the lockbox; fakes judged by impossible length for the kind (real Anthropic keys # ~108 chars, OpenAI 51 or 160+), fake-words, or identity with upstream public # fixtures. NOT allowed, remove instead: 1354fc9b (old @Windy_0_bot token) and # d49dc2ba (old Anthropic key), both real and revoked, in public windy-agent. allow: - repo: windy-code hashes: [ac9265e5, 46eb1235] reason: "Upstream microsoft/vscode terminalEnvironment.test.ts fixtures (identical hash upstream; public)." - repo: windy-code paths: ["build/azure-pipelines/common/publish.ts"] kinds: [private key block] reason: "Upstream VS Code build script (PEM header string in code, not a key)." - repo: windy-agent hashes: [a9235a6d, dd6a2baa, 02c362d8, a6f6ff79, f7503b21, d0c94833, 4ab092e3, e3aa1eb8, 833382ee] reason: "Redaction/sanitizer test fixtures; lengths impossible for real Anthropic/OpenAI keys; never in the lockbox." - repo: windy-agent hashes: [89bd408f, b8c94b72, bf23cdf5, d1d85dfe, e3e07f06] reason: "09-24 #395 replacement fixtures (each contains FAKE; token-SHAPED on purpose so redaction tests prove real tokens are scrubbed); verified by Windy Agent sha-for-sha against every lockbox version: never real. Weekly scan 09-28." - repo: windy-agent paths: ["tests/test_agent_keys.py"] kinds: [private key block] reason: "Test-generated key material for agent-key tests." - repo: windy-mind hashes: [f8a630b2] reason: "Provider test fixture (27 chars; a real Anthropic key is ~108)." - repo: windy-pro hashes: [756de8d8, 7828319d, 1a5d44a2] reason: ".env.production.example placeholder + crash-summary test fixtures (AWS doc EXAMPLE key shape, short fake Slack token)." - repo: windy-pro paths: ["account-server/docs/oauth-providers.md"] kinds: [private key block] reason: "Docs show the PEM header format; no key material." - repo: windytalk hashes: [baf8656a] reason: "Diagnostics redaction test fixture (fake-word in value)." - repo: eternitas paths: ["tests/golden_vectors/**", "tests/test_soul_vault_key_separation.py"] kinds: [private key block] reason: "Test vectors and throwaway keys for signature/vault tests." - repo: windy-drops paths: ["tools/conformance/test-keys/*"] kinds: [private key block] reason: "Conformance-suite test keys (named test-private.pem)." - repo: windy-git paths: ["api/tests/test_secret_guard.py"] kinds: [private key block] reason: "The guard's own test uses a PEM header string as a sample." - repo: windy-code hashes: ["23f32607"] reason: "VS Code OSS extensions' package.json aiKey: Microsoft's public telemetry (App Insights) key, shipped in every VS Code build; not a Windy credential." - repo: windytalk hashes: ["c4189d79"] reason: "apps/desktop/test/diagnostics.test.ts redaction fixture (hexSecret beside a fake sk-ant token); hash checked against the lockbox 10-01: not present." - repo: windy-agent hashes: ["84e0c0ea"] reason: "tests/test_log_redaction.py:56 Z.ai redaction fixture REPLACED by windy-agent #412 with a synthetic value; hash checked against the lockbox 10-01: not present."